Forcing users through Dansguardian and Squid Using IPTables

Hi i need to send my clients through dansguardian and squid without any configuration on the client machines.

i havent tested the following rules, i would like somebody to check over them beforehand. and point out what can be improved and where.

Thanks in advanced.


iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 -j REDIRECT --to-port 8080
iptables -A INPUT -j ACCEPT -m state --state NEW,ESTABLISHED,RELATED -o eth1 -p tcp --dport 8080
iptables -A OUTPUT -j ACCEPT -m state --state NEW,ESTABLISHED,RELATED -o eth0 -p tcp --dport 80
iptables -A INPUT -j ACCPET -m state --state ESTABLISHED,RELATED -i eth0 -p tcp --sport 80
iptables -A OUTPUT -j ACCEPT -m state --state ESTABLISHED,RELATED -o eth1 -p tcp --sport 80

Open in new window

CNTPL89Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

LinuxNtwrkngCommented:
It all looks good to me
0
CNTPL89Author Commented:
i get an error on the second rule saying i cant use a -o on a input, i used -p instead, this doesnt work. any ideas?
0
LinuxNtwrkngCommented:
Right.. sorry I missed that.  The "-o" on the second line should be "-i".  You have the INPUT chain, as you should, but the "-o" specifies that traffic will be going out that interface.  It will not, it will be coming in to it from your workstations.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Linux Distributions

From novice to tech pro — start learning today.